---
id: CVE-2026-94545
title: Satori is a library to convert HTML and CSS to SVG
summary: >-
  Satori is a library to convert HTML and CSS to SVG. Starting in version 0.0.27
  and prior to version 0.33.5, Satori does not properly escape certain values
  before including them in generated SVG output. This can allow crafted values
  to be…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N'
cwe:
  - CWE-116
vendor: vercel
product: satori
affected:
  - 'satori >= 0.0.27, < 0.33.5'
  - 'next >= 16.2.0, < 16.3.6'
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T16:19:25.770'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-94545'
references:
  - url: >-
      https://github.com/vercel/next.js/commit/868fad38690d72088868f299fa2bef339b26838e
    label: security-advisories@github.com
  - url: 'https://github.com/vercel/next.js/releases/tag/v16.3.6'
    label: security-advisories@github.com
  - url: 'https://github.com/vercel/next.js/security/advisories/GHSA-vcvr-r3jv-pc5j'
    label: security-advisories@github.com
  - url: >-
      https://github.com/vercel/satori/commit/26a52affc031216fee5882b6e965c8dbc7ac1782
    label: security-advisories@github.com
  - url: 'https://github.com/vercel/satori/pull/814'
    label: security-advisories@github.com
  - url: 'https://github.com/vercel/satori/security/advisories/GHSA-wx4j-mvgx-mqwp'
    label: security-advisories@github.com
tags:
  - nvd
  - exploit-available
  - cve.org
exploits:
  github: 4
  githubRepos:
    - 'https://github.com/EQSTLab/CVE-2026-94545'
    - 'https://github.com/HORKimhab/CVE-2026-94545'
    - 'https://github.com/Hassham1/CVE-2026-94545-nextjs-og-poc'
  checkedAt: '2026-09-30T17:13:56.221Z'
exploitAvailable: true
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-30T15:41:03.767825Z'
cvssSource: cna
ingestedAt: '2026-09-30T15:07:05.374Z'
---

## Overview

Satori is a library to convert HTML and CSS to SVG. Starting in version 0.0.27 and prior to version 0.33.5, Satori does not properly escape certain values before including them in generated SVG output. This can allow crafted values to be interpreted as SVG markup. The impact depends on how the generated SVG is consumed. Version 0.33.5 contains a patch. No complete workaround exists besides upgrading. Applications that cannot immediately upgrade should not render attacker-controlled content with Satori.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
